[Detection Rules] Add 8.5 rules (#142239)

Co-authored-by: Mika Ayenson <Mikaayenson@users.noreply.github.com>
This commit is contained in:
Terrance DeJesus 2022-09-29 16:05:22 -04:00 committed by GitHub
parent 1bf14d7ab8
commit 907c1059ba
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
193 changed files with 413 additions and 389 deletions

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -81,5 +81,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -20,8 +20,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -72,5 +73,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -20,8 +20,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -72,5 +73,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "google_workspace",
"version": "1.2.0"
"version": "^1.2.0"
}
],
"required_fields": [
@ -86,5 +86,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 1
"version": 2
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "google_workspace",
"version": "1.2.0"
"version": "^1.2.0"
}
],
"required_fields": [
@ -86,5 +86,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 1
"version": 2
}

View file

@ -27,7 +27,7 @@
"related_integrations": [
{
"package": "o365",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -110,5 +110,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
{
"integration": "activitylogs",
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -89,5 +89,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -19,7 +19,7 @@
"related_integrations": [
{
"package": "okta",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -65,5 +65,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -22,7 +22,7 @@
"related_integrations": [
{
"package": "okta",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -73,5 +73,5 @@
"value": 3
},
"type": "threshold",
"version": 100
"version": 101
}

View file

@ -21,7 +21,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -86,5 +86,5 @@
"value": 25
},
"type": "threshold",
"version": 101
"version": 102
}

View file

@ -23,7 +23,7 @@
{
"integration": "activitylogs",
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -74,5 +74,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -24,7 +24,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -92,5 +92,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 101
"version": 102
}

View file

@ -24,7 +24,7 @@
{
"integration": "activitylogs",
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -82,5 +82,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -24,7 +24,7 @@
"related_integrations": [
{
"package": "o365",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -90,5 +90,5 @@
"value": 10
},
"type": "threshold",
"version": 100
"version": 101
}

View file

@ -19,7 +19,7 @@
"related_integrations": [
{
"package": "o365",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -80,5 +80,5 @@
"value": 25
},
"type": "threshold",
"version": 100
"version": 101
}

View file

@ -22,7 +22,7 @@
"related_integrations": [
{
"package": "okta",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -78,5 +78,5 @@
"value": 25
},
"type": "threshold",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -89,5 +89,5 @@
"value": 10
},
"type": "threshold",
"version": 100
"version": 101
}

View file

@ -26,7 +26,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -79,5 +79,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 101
"version": 102
}

View file

@ -23,7 +23,7 @@
{
"integration": "activitylogs",
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -74,5 +74,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -20,7 +20,7 @@
"related_integrations": [
{
"package": "o365",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -81,5 +81,5 @@
"value": 5
},
"type": "threshold",
"version": 100
"version": 101
}

View file

@ -20,7 +20,7 @@
"related_integrations": [
{
"package": "okta",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -61,5 +61,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "google_workspace",
"version": "1.2.0"
"version": "^1.2.0"
}
],
"required_fields": [
@ -102,5 +102,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 1
"version": 2
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "okta",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -77,5 +77,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "okta",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -77,5 +77,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -22,7 +22,7 @@
"related_integrations": [
{
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -80,5 +80,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
{
"integration": "activitylogs",
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -69,5 +69,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -22,7 +22,7 @@
{
"integration": "activitylogs",
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -73,5 +73,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
{
"integration": "activitylogs",
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -81,5 +81,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -82,5 +82,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 101
"version": 102
}

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -89,5 +89,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 101
"version": 102
}

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -89,5 +89,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 101
"version": 102
}

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -89,5 +89,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 101
"version": 102
}

View file

@ -26,7 +26,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -85,5 +85,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 101
"version": 102
}

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -88,5 +88,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "google_workspace",
"version": "1.2.0"
"version": "^1.2.0"
}
],
"required_fields": [
@ -87,5 +87,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -89,5 +89,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 101
"version": 102
}

View file

@ -27,7 +27,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -90,5 +90,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -24,7 +24,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -87,5 +87,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -24,7 +24,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -87,5 +87,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -25,7 +25,7 @@
{
"integration": "activitylogs",
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -83,5 +83,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
{
"integration": "activitylogs",
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -81,5 +81,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
{
"integration": "activitylogs",
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -81,5 +81,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -21,8 +21,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -68,5 +69,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -21,8 +21,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -68,5 +69,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -21,8 +21,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -68,5 +69,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -21,8 +21,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -73,5 +74,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -20,8 +20,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -72,5 +73,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -20,8 +20,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -72,5 +73,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -20,8 +20,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -72,5 +73,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -20,8 +20,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -73,5 +74,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -20,8 +20,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -72,5 +73,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -20,8 +20,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -80,5 +81,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -21,8 +21,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -76,5 +77,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -21,8 +21,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -81,5 +82,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "google_workspace",
"version": "1.2.0"
"version": "^1.2.0"
}
],
"required_fields": [
@ -92,5 +92,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 1
"version": 2
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "google_workspace",
"version": "1.2.0"
"version": "^1.2.0"
}
],
"required_fields": [
@ -102,5 +102,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 1
"version": 2
}

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -88,5 +88,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
{
"integration": "activitylogs",
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -81,5 +81,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "o365",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -84,5 +84,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -22,7 +22,7 @@
"related_integrations": [
{
"package": "o365",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -83,5 +83,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "o365",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -84,5 +84,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -22,7 +22,7 @@
"related_integrations": [
{
"package": "o365",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -83,5 +83,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -22,7 +22,7 @@
"related_integrations": [
{
"package": "o365",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -85,5 +85,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
{
"integration": "activitylogs",
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -81,5 +81,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "okta",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -77,5 +77,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "okta",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -77,5 +77,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "okta",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -77,5 +77,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "okta",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -77,5 +77,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "okta",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -77,5 +77,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -22,7 +22,7 @@
"related_integrations": [
{
"package": "okta",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -76,5 +76,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "okta",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -77,5 +77,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -28,7 +28,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -84,5 +84,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -24,7 +24,7 @@
{
"integration": "activitylogs",
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -75,5 +75,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -25,7 +25,7 @@
"related_integrations": [
{
"package": "okta",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -106,5 +106,5 @@
"value": 5
},
"type": "threshold",
"version": 100
"version": 101
}

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -83,5 +83,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -88,5 +88,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
{
"integration": "activitylogs",
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -89,5 +89,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -21,7 +21,7 @@
"related_integrations": [
{
"package": "kubernetes",
"version": "1.17.2"
"version": "^1.4.1"
}
],
"required_fields": [
@ -70,5 +70,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 1
"version": 2
}

View file

@ -25,7 +25,7 @@
{
"integration": "activitylogs",
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -76,5 +76,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -26,7 +26,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -97,5 +97,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -78,5 +78,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 101
"version": 102
}

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -96,5 +96,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -20,8 +20,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -72,5 +73,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "o365",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -84,5 +84,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -24,7 +24,7 @@
"related_integrations": [
{
"package": "o365",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -85,5 +85,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -76,5 +76,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -87,5 +87,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -22,7 +22,7 @@
"related_integrations": [
{
"package": "okta",
"version": "1.3.0"
"version": "^1.3.0"
}
],
"required_fields": [
@ -68,5 +68,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -24,7 +24,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -81,5 +81,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -24,7 +24,7 @@
"related_integrations": [
{
"package": "azure",
"version": "0.12.0"
"version": "^1.0.0"
}
],
"required_fields": [
@ -75,5 +75,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -104,5 +104,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 101
"version": 102
}

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -104,5 +104,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 101
"version": 102
}

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -105,5 +105,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 101
"version": 102
}

View file

@ -26,7 +26,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -89,5 +89,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -25,7 +25,7 @@
{
"integration": "cloudtrail",
"package": "aws",
"version": "1.10.2"
"version": "^1.5.0"
}
],
"required_fields": [
@ -81,5 +81,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -20,8 +20,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -72,5 +73,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -20,8 +20,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -72,5 +73,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -20,8 +20,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -72,5 +73,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -20,8 +20,9 @@
],
"related_integrations": [
{
"integration": "audit",
"package": "gcp",
"version": "1.10.0"
"version": "^2.2.1"
}
],
"required_fields": [
@ -67,5 +68,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

View file

@ -23,7 +23,7 @@
"related_integrations": [
{
"package": "google_workspace",
"version": "1.2.0"
"version": "^1.2.0"
}
],
"required_fields": [
@ -80,5 +80,5 @@
],
"timestamp_override": "event.ingested",
"type": "query",
"version": 100
"version": 101
}

Some files were not shown because too many files have changed in this diff Show more